Two U.S. Air Force members were sentenced to prison for running a business email compromise (BEC) scheme that stole more than $2 million. They phished businesses to steal email logins, then took over real email threads and sent "updated" wiring instructions to redirect large payments into accounts they controlled.
How the attack worked
This case involved two U.S. Air Force members who ran a business email compromise scheme that stole more than $2 million from at least 15 organizations. The scheme began with phishing emails sent to businesses in order to steal login credentials for employee email accounts. Once inside a mailbox, the attackers did not act immediately. Instead, they watched for discussions of payments, waiting for the right moment to intervene in an active transaction.
When a payment conversation appeared, the attackers inserted themselves into the existing email chain and sent "updated" wiring information, using the stolen credentials and spoofed email addresses to make the request appear to come from a trusted business partner. Prosecutors cited diverted payments including a $1.7 million wire and a $720,000 wire as part of the scheme. Stolen financial data, including account numbers and card information, was also used for purchases or sold to other criminals.
Why it succeeded
The scheme worked because it exploited trust that already existed inside real conversations rather than trying to create trust from scratch. Key factors included:
- Compromised or spoofed email addresses that appeared to belong to a known vendor or business partner
- Requests embedded inside an active, ongoing invoice or payment thread rather than sent as a new, suspicious email
- Timing tied to real payment discussions the attackers were monitoring inside breached mailboxes
Because the fraudulent request arrived as a continuation of a legitimate exchange, it bypassed the natural skepticism people apply to unexpected or out-of-context messages.
What to watch for
Finance, accounts payable, accounting, procurement and executive staff handling payments should treat these signals as red flags:
- Bank or wiring details that change mid-transaction, especially late in a payment process
- A sender address that looks correct but may be spoofed or come from a compromised mailbox
- Wiring changes introduced inside an existing thread instead of through a separate, verified channel
How to build resistance
Organizations can reduce exposure to this pattern with a few concrete steps:
- Treat any change to wiring instructions as high risk and verify it using a trusted, out-of-band method such as a known phone number or vendor portal, even if the request appears inside a familiar email thread
- Train staff to recognize and report credential-harvesting phishing attempts, since stolen logins are what make these impersonations convincing
- Limit who is authorized to change payment instructions and require additional approval for high-dollar transfers, since attackers may be monitoring mailboxes for the right moment to strike
These practices address the specific mechanics seen in this case: credential theft, email thread hijacking, and mid-transaction payment redirection.
Key findings
- Attackers sent phishing emails to businesses to steal employee email account credentials.
- They used stolen credentials and spoofed email addresses to take over email chains and redirect legitimate payments.
- They monitored inboxes for payment conversations and inserted themselves into existing threads with "updated" wiring information.
- At least 15 organizations were targeted; prosecutors cited diverted payments including $1.7M and $720K wires.
- Stolen financial data (account numbers, credit/debit card info) was used for purchases or sold to other criminals.
Who’s being targeted
- Commonly targeted roles: Finance, Accounts Payable, Accounting, Procurement/Vendor Management, Executive assistants involved in payments.
- Affected industries: Multiple industries (various victim organizations).
- Attack channels: email.
- Impersonated: A known business partner/vendor (using a compromised or spoofed email identity).
Red flags to watch for
- Bank/wiring details change during an active invoice/payment conversation
- Sender address may be spoofed or coming from a compromised mailbox while appearing to be a trusted partner
- Request is embedded inside an existing email thread to look legitimate
Frequently asked questions
How did the attackers steal money without hacking bank accounts?
They phished businesses to steal employee email credentials, then used those logins and spoofed addresses to take over existing email threads and insert fake wiring instructions into legitimate payment conversations.
What made this business email compromise scheme effective?
The attackers monitored compromised inboxes for payment discussions and inserted themselves into ongoing threads with updated wiring details, making the fraudulent request look like a natural continuation of a trusted conversation.
How can organizations defend against this kind of wire fraud?
Treat any change to wiring instructions as high risk and verify it through a trusted, out-of-band channel such as a known phone number, and limit who is authorized to approve changes to payment details.
Who is most at risk from this type of attack?
Finance, accounts payable, accounting, procurement, and executive assistants who handle payments are the primary targets since they are the ones acting on wiring instructions.
Read the video transcript
Two Air Force members just got jailed for a $2 million scam that started with one innocent-looking email. They phished employee logins, sat inside real inboxes, watched payment threads, then replied in the same email chain: 'Hi, please use the updated wiring information for this payment going forward.' Here’s the trap: the email comes from the real thread, the real name, the real invoice details, only the bank account is swapped, sending money to them instead of your vendor. If wiring details ever change mid-email thread, stop. Call the vendor on a known phone number you already trust and confirm before you move a cent.